CVE-2026-61568Critical· 9.6▾ Midnight`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route bro…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
@zereight/mcp-gitlab is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP listener while preserving an attacker-controlled Host and Origin. The server accepts those headers and reaches the MCP initialization path instead of rejecting the request at the HTTP boundary. Version 2.1.30 contains a patch.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@zereight/mcp-gitlab < 2.1.30Patched in:
@zereight/mcp-gitlab 2.1.30Connected by shared product, vendor, weakness, or advisory.
GHSA-5648-rgj9-v224High· 8.1@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
CVE-2026-61560Critical· 9.8`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
CVE-2026-61559Critical· 9.6`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab
CVE-2026-61743Medium· 6.3Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts
CVE-2026-53708Medium· 6.6ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for MCP, A2A, and REST or gRPC APIs
CVE-2026-57123Critical· 9.8PraisonAI is a multi-agent teams system